Microsoft breaks Patch Tuesday record with 974-CVE deluge
Adobe also brought goodies to the patch party and they deserve immediate attention
Microsoft delivered a staggering 974 security patches in a single month, surpassing even its own previous record. Among these updates were two vulnerabilities already being exploited by attackers. The month's patch drop follows a trend of increasing security fixes, with Microsoft releasing 421 patches in August and 622 in July. Adobe also made headlines with 10 bulletins addressing 172 CVEs, including a critical zero-day vulnerability known as StyleSmuggler.
This flaw allows unauthenticated attackers to execute remote code on Magento and Adobe Commerce platforms. Microsoft's record-breaking 974 CVEs include several high-severity vulnerabilities that could grant attackers administrative privileges. Two of these flaws are already being exploited as zero-days. Microsoft's disclosure of these vulnerabilities has prompted federal agencies to prioritize patching within specific deadlines.
However, one vulnerability - CVE-2026-85046 - remains unpatched in Microsoft's Edge browser. Google patched this issue in Chrome, but Microsoft has not published an advisory for it. This omission leaves users uncertain about their protection status.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Microsoft breaks Patch Tuesday record with 974-CVE deluge theregister.com
- Why this month's Microsoft patch release is a doozy arstechnica.com
- Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited therecord.media